Security Patches for Umbraco Forms are now available
Patch ready for Umbraco Forms version 13, 17, and 18.
Who’s affected?
Versions affected:
Umbraco Forms 13.0.0 - 13.9.7
Umbraco Forms 17.0.0 - 17.4.6
Umbraco Forms 18.0.0 - 18.0.4
Unsupported versions can be subject to the vulnerability, but will not receive a patch. We recommend upgrading to a supported major version if you are using the affected features.
How to fix the vulnerability
If you’re using Umbraco Forms versions 13.9, 17.4, or 18.0, you are able to upgrade to a new patch version of these releases the way you would normally upgrade.
How do you check which version you are on? Reach out to your technical contact for your Umbraco site with this blog post, and they will be able to take care of the necessary precautions.
If your Umbraco project is hosted on Umbraco Cloud, an automatic upgrade will be rolled out today - no action needed.
What we know about the vulnerability
A flaw in Umbraco Forms' handling of form submissions allowed the multi-page progression to be manipulated so that the server treated a form as complete prematurely. As a result, an unauthenticated user could finalise a submission without completing the intended submission flow.
Under this condition, server-side validation checks that normally run before a submission is accepted could be bypassed, and a form could be submitted in an incomplete or unverified state. Associated post-submission actions (such as configured workflows) could still be triggered. This affects both single-page and multi-page forms.
The severity of this vulnerability is: High. The issue is remotely exploitable by an unauthenticated user, reliably reproducible, and bypasses submission safeguards while still producing a stored submission and triggering downstream actions.
Credit
We'd like to thank Ismael Machuca for reporting the issues and for responsible disclosure of details regarding the vulnerability.
Any questions?
If you have any questions or comments about this advisory, make sure to get in touch with us directly on the Security Advisories. Alternatively, you can reach out to the dedicated security email address listed at https://umbraco.com/security. Here you can also find information on how we handle security-related issues.
For direct communication related to security in Umbraco products, please sign up for the dedicated security mailing list.